VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 94 of 169
  • CVE-2024-31916HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

  • CVE-2024-37368HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this…

  • CVE-2024-1662HigJun 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Application allows Retrieve Embedded Sensitive Data. This issue affects PowerBank Application: before 2.02.

  • CVE-2024-27942HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system,…

  • CVE-2022-32503HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.

  • CVE-2023-44413HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.02

    D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-1491HigApr 18, 2024
    risk 0.49cvss 7.5epss 0.01

    The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal…

  • CVE-2024-21007HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2024-21006HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.08

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-4857HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.

  • CVE-2023-51571HigApr 1, 2024
    risk 0.49cvss 7.5epss 0.01

    Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to…

  • CVE-2022-48621HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49115HigFeb 1, 2024
    risk 0.49cvss 7.5epss 0.01

    MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

  • CVE-2023-6942HigJan 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX…

  • CVE-2023-40393HigJan 10, 2024
    risk 0.49cvss 7.5epss 0.01

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2023-6595HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

  • CVE-2023-46978HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.

  • CVE-2023-40401HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys without authentication.

  • CVE-2023-39930HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.

  • CVE-2023-27377HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.